Database/AI/ML frameworks & serving

llama-server (tokenization endpoints): Use-after-free across six tokenization endpoints
CVSS 8.1CVE-2026-43632AI/ML frameworks & servingcurated
Impact
Use-after-free across six tokenization endpoints
Who can reach it
Unauthenticated network to llama-server
What to do
Rebuild past b9060
References
Related entries
- NVIDIA NemoClaw: installation process executes untrusted codeCVE-2026-65081 · NVIDIA NemoClaw for Linux (installer)High
- NVIDIA NemoClaw: deployment process fails to validate certificates properlyCVE-2026-65084 · NVIDIA NemoClaw for Linux (deployment process, TLS certificate validation)High
- NVIDIA NemoClaw: weak authentication in the remote-access helper workflowCVE-2026-65098 · NVIDIA NemoClaw for Linux (remote-access helper workflow)High
- NVIDIA NemoClaw: inference service comes up without authentication, reachable from the adjacent networkCVE-2026-65105 · NVIDIA NemoClaw for Linux (inference server setup)High
- Bifrost LLM gateway: unauthenticated plugin API loads a remote shared object, giving RCE on dynamic buildsCVE-2026-86242 · Bifrost LLM gateway (HTTP transport /api/plugins shared-object loader)High
- ClearML client SDK: Deserialization of untrusted dataCVE-2024-24590 · ClearML client SDKHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.